Hybrid Email Policy Device for Cloud Scanning and Local Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures face challenges in effectively protecting computer networks from both inbound and outbound email threats, with cloud email services providing limited synchronization of network-specific configurations and separate administrative burdens for inbound and outbound email protections.
Innovation Solution
A communication system that integrates cloud email scanning with local policy application, allowing inbound emails to be scanned by cloud services and evaluated locally, with outbound emails filtered before leaving the network, using an email policy device that applies network-specific policies and reports threats in real-time without storing user configurations elsewhere.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If cloud services are used for email filtering, then bandwidth consumption is reduced, but network-specific policy application and configuration synchronization are limited
Solution Approach 1:
The system divides email filtering into two segments: cloud-based initial filtering (spam, malware) and local policy-based filtering (network-specific rules). This segmentation allows bandwidth savings from cloud filtering while maintaining adaptability through local policy enforcement on inbound and outbound emails.
Solution Approach 2:
The system merges cloud email filtering services with local on-premise email policy enforcement in a hybrid architecture. The local email policy device receives, sends, and forwards emails while applying network-specific policies, combining the benefits of both cloud and local solutions.
2Reliability
If separate mechanisms are used for inbound and outbound email protection, then comprehensive coverage is achieved, but administrative complexity increases
Solution Approach 1:
The local email policy device performs multiple functions: receiving inbound emails, sending outbound emails, applying inbound policies, applying outbound policies, and forwarding emails. This multi-functionality provides comprehensive email protection while simplifying administration through a single device interface.
3Measurement precision
If cloud scanning is used, then initial threat detection is improved, but real-time local policy enforcement and configuration management are weakened
Solution Approach 1:
The system implements feedback by having the local email policy device receive scan results from cloud services and apply local policies based on those results. The local device enforces network-specific policies in real-time and can request additional scanning, creating a feedback loop that maintains both detection accuracy and local control.
Data Source
AI summary
A method for applying policies to an email message includes receiving, by an inbound policy module in a protected network, message metadata of an email message. The method also includes determining, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy. The method further includes blocking the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the metadata policy. In specific embodiments, the method includes requesting scan results data for the email message if receiving the email message in the protected network is not prohibited by one or more metadata policies. In further embodiments, the method includes receiving the scan results data and requesting the email message if receiving the email message in the protected network is not prohibited by one or more scan policies.


